SUSE-SU-2023:4371-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4371-1
SUSE-SU-2023:4371-1
Summary: Security update for tiff
Details: This update for tiff fixes the following issues: - CVE-2023-38289: Fixed a NULL pointer dereference in raw2tiff (bsc#1213589). - CVE-2023-38288: Fixed an integer overflow in raw2tiff (bsc#1213590). - CVE-2023-3576: Fixed a memory leak in tiffcrop (bsc#1213273). - CVE-2020-18768: Fixed an out of bounds read in tiffcp (bsc#1214574). - CVE-2023-26966: Fixed an out of bounds read when transforming a little-endian file to a big-endian output (bsc#1212881) - CVE-2023-3618: Fixed a NULL pointer dereference while encoding FAX3 files (bsc#1213274). - CVE-2023-2908: Fixed an undefined behavior issue when doing pointer arithmetic on a NULL pointer (bsc#1212888). - CVE-2023-3316: Fixed a NULL pointer dereference while opening a file in an inaccessible path (bsc#1212535). - CVE-2023-25433: Fixed a buffer overflow in tiffcrop (bsc#1212883).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234371-1/, https://bugzilla.suse.com/1212535, https://bugzilla.suse.com/1212881, https://bugzilla.suse.com/1212883, https://bugzilla.suse.com/1212888, https://bugzilla.suse.com/1213273, https://bugzilla.suse.com/1213274, https://bugzilla.suse.com/1213589, https://bugzilla.suse.com/1213590, https://bugzilla.suse.com/1214574, https://www.suse.com/security/cve/CVE-2020-18768, https://www.suse.com/security/cve/CVE-2023-25433, https://www.suse.com/security/cve/CVE-2023-26966, https://www.suse.com/security/cve/CVE-2023-2908, https://www.suse.com/security/cve/CVE-2023-3316, https://www.suse.com/security/cve/CVE-2023-3576, https://www.suse.com/security/cve/CVE-2023-3618, https://www.suse.com/security/cve/CVE-2023-38288, https://www.suse.com/security/cve/CVE-2023-38289
Affected packages
Package
Name: tiff
Purl: pkg:rpm/suse/tiff&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
